Skip to content

Privacy Policy

Last updated: 3 June 2026

This Privacy Policy explains how MacroVector Ltd (“MacroFinance”, “we”, “us”, “our”) collects, uses, and shares personal data when you use macrofinance.ai and our related services (the “Service”).

Data controller. MacroVector Ltd, a company registered in England and Wales with company number 09602791, registered office at Harwood House, 43 Harwood Road, London SW6 4QP, United Kingdom. Contact: [email protected].

This Policy is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Personal data we collect

(a) Information you provide directly:

  • Account details: name, email address, password (stored encrypted), company, professional role, sector, country.
  • Billing information: name and email passed to Stripe; we do not store full card numbers. Stripe stores a customer ID we associate with your Account.
  • Communications: any messages you send us via forms or email.

(b) Information collected automatically:

  • Technical data: IP address, browser type and version, device and operating system, referrer URL, pages viewed, time and date of access, language.
  • Usage data: features used, AI queries, login times, API requests.
  • Cookies and similar identifiers (see section 6).

(c) Information from third parties:

  • Social login: if you sign in with Google (via Nextend Social Login), we receive your name, email, and profile picture from Google.
  • IP geolocation: at sign-up we look up the country for your IP via ip-api.com (country level only).
  • Payment confirmation events from Stripe.

We do not knowingly collect special-category data (e.g., health, biometric, political opinions) and ask you not to provide it.

2. How we use personal data and our legal bases

PurposeCategories usedLegal basis (UK GDPR Art. 6)
Create and operate your AccountAccount detailsContract
Process payments and manage SubscriptionsAccount, billingContract
Provide the Service, AI features, and APIsAll categoriesContract
Send service emails (verification, activation, password reset, receipts)AccountContract
Send newsletters and product marketingEmailConsent (you may unsubscribe at any time)
Prevent abuse, fraud, and security incidentsTechnical, usageLegitimate interests
Comply with legal obligations (e.g., tax, accounting)BillingLegal obligation
Improve the Service and develop featuresUsage, technicalLegitimate interests
Sign-up location signal (country)IPLegitimate interests

Where we rely on legitimate interests, we have assessed that those interests are not overridden by your rights and freedoms.

3. Who we share personal data with

We share personal data only with the categories of recipients below, and only to the extent necessary for the purposes set out above. We do not sell your personal data.

RecipientPurposeLocationSafeguards
Stripe Payments Europe / Stripe, Inc.Payment processingEU / USStandard Contractual Clauses; UK addendum
Google LLC (reCAPTCHA, Sign-in, Site Kit / Analytics)Anti-spam, social login, analyticsUSStandard Contractual Clauses; UK addendum
Hetzner Online GmbHHosting and email delivery (SMTP)FinlandData Processing Agreement; EU GDPR-compliant data centre
ip-api.comCountry lookup at sign-upUSOnly the IP is sent; single lookup, no identifier
WordfenceSite security and firewallUSStandard Contractual Clauses
Backup providersStoring site backupsEUContractual data-protection terms
Professional advisers, auditorsLegal and accounting complianceUKConfidentiality and contractual terms
Tax, regulatory, or law-enforcement authoritiesWhere required by lawUK

If we ever sell or transfer the business or its assets, personal data may be transferred to the acquirer subject to the same protections.

4. International transfers

Some recipients (e.g., Stripe, Google) process personal data outside the UK, typically in the EEA and the US. Where we transfer personal data outside the UK, we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another approved mechanism, and take additional measures where required.

5. How long we keep personal data

  • Account data: while your Account is active and for up to 12 months after closure, then deleted or anonymised, unless we must retain it longer to comply with legal obligations.
  • Billing and tax records: 7 years (HMRC requirement).
  • Security and abuse-prevention logs: up to 12 months.
  • Marketing data: until you withdraw consent or unsubscribe.
  • Backups: up to 90 days, after which backup snapshots are overwritten.

6. Cookies and similar technologies

We use cookies and similar identifiers to operate the Service, remember your preferences, secure your session, and (with your consent where required) measure usage.

Categories we use:

  • Strictly necessary cookies: session, authentication, security, load balancing. These cannot be disabled without breaking the Service.
  • Analytics: usage measurement (via Google Site Kit / Analytics).
  • Marketing-attribution cookies we set: mf_tp1, mf_signup_source_url, pm_signup_source_url, pm_signup_source_post. These record how you arrived on the site so we can credit a referring page when you sign up.

You can manage cookies in your browser settings. Where required by law, we will request your consent before setting non-essential cookies.

7. Your rights

Under the UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate personal data.
  • Request erasure (the “right to be forgotten”) where applicable.
  • Restrict or object to processing where applicable.
  • Receive your data in a portable format where applicable.
  • Withdraw consent at any time (without affecting prior processing).
  • Object to direct marketing at any time.

To exercise these rights, contact us at [email protected]. We will respond within one month.

If you are unhappy with how we process your data, you can complain to the Information Commissioner’s Office (ICO) — https://ico.org.uk — though we ask that you contact us first so we can try to resolve the issue.

8. Automated decision-making and AI

We do not carry out automated decision-making that produces legal or similarly significant effects on you. AI features in the Service generate informational outputs only; we do not use AI to decide whether to grant or withhold any contractual benefit.

9. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, the Wordfence firewall, password hashing, and security monitoring. No system is 100% secure; please keep your credentials confidential and notify us of any suspected breach.

10. Children

The Service is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to this Policy

We may update this Policy from time to time. We will post the new version on this page and update the “Last updated” date. If the change is material we will give you reasonable notice (e.g., by email or in-product notice).

12. Contact

All privacy questions and requests: [email protected]

You can also write to us at: Data Protection, MacroVector Ltd, Harwood House, 43 Harwood Road, London SW6 4QP, United Kingdom.

You can complain to the Information Commissioner’s Office (ICO) at any time: https://ico.org.uk · 0303 123 1113.